ComboFix 08-07-28.6 - Norma Smith 2008-07-31 21:39:04.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.534 [GMT -4:00]
Running from: C:\Documents and Settings\Norma Smith\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Norma Smith\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\avgrsstx(2).dll
C:\Documents and Settings\Nicole\Start Menu\Programs\Startup\ :#:
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\punyjmfo
C:\Documents and Settings\All Users\Application Data\punyjmfo\votifijq.exe
C:\Documents and Settings\Chelsea Smith\Application Data\Viewpoint
C:\Documents and Settings\Chelsea Smith\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\URLCache.ini
C:\Documents and Settings\Chelsea Smith\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\URLCache.ini
C:\Documents and Settings\Chelsea Smith\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\URLCache.ini
C:\Documents and Settings\Chelsea Smith\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\URLCache.ini
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\avglinks.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\avglogo.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\avgstatus.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\avgstatus_error.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\brandlogo.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\p_yahoo.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\safesearch.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\safesearch_off.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\safesearch_on.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\safesurf.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\safesurf_off.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\safesurf_on.bmp
C:\Documents and Settings\Norma Smith\Application Data\AVGTOOLBAR\slider.bmp
C:\Documents and Settings\Norma Smith\Application Data\macromedia\Flash Player\#SharedObjects\5JV77V33\interclick.com
C:\Documents and Settings\Norma Smith\Application Data\macromedia\Flash Player\#SharedObjects\5JV77V33\interclick.com\ud.sol
C:\Documents and Settings\Norma Smith\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Norma Smith\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\MDT
C:\MDT\MSetting.ini
C:\MDT\path.ini
C:\MDT\Setting.ini
C:\Program Files\Full Tilt Poker
C:\Program Files\Full Tilt Poker\Cache\42D4EB830001.dc
C:\Program Files\Full Tilt Poker\njsmith999.dat
C:\Program Files\Full Tilt Poker\stand1.dat
C:\Program Files\nvtkmz
C:\Program Files\nvtkmz\DscCmdMon.dll
C:\WINDOWS\system32\7889
C:\WINDOWS\system32\avgrsstx(2).dll
C:\WINDOWS\system32\delete.exe
C:\WINDOWS\system32\drivers\Avg(2)
C:\WINDOWS\system32\drivers\Avg(2)\avi7.avg
C:\WINDOWS\system32\drivers\Avg(2)\incavi.avm
C:\WINDOWS\system32\drivers\Avg(2)\microavi.avg
C:\WINDOWS\system32\drivers\Avg(2)\miniavi.avg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NOBICYT
-------\Service_NOBICYT
((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))
.
2008-07-31 21:16 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-31 21:14 . 2008-07-31 21:14 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-29 10:42 . 2008-07-29 10:42 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-29 10:42 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-29 10:42 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-29 02:02 . 2008-07-29 02:02 <DIR> d-------- C:\Documents and Settings\Nicole\Application Data\Malwarebytes
2008-07-27 18:36 . 2008-07-27 18:36 <DIR> d-------- C:\Documents and Settings\Norma Smith\Application Data\Malwarebytes
2008-07-27 18:36 . 2008-07-27 18:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-26 10:49 . 2008-07-31 21:46 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-26 10:49 . 2008-07-26 10:49 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-22 09:21 . 2008-07-22 09:21 <DIR> d-------- C:\Documents and Settings\Norma Smith\Application Data\Uniblue
2008-07-22 09:21 . 2008-07-22 09:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-07-17 10:09 . 2008-07-31 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Dl_cats
2008-07-17 10:08 . 2008-07-17 10:08 <DIR> d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-07-12 10:38 . 2008-07-12 10:38 <DIR> d-------- C:\Program Files\Minutes Matter Solutions
2008-07-10 08:02 . 2008-07-10 08:02 137 --a------ C:\WINDOWS\system32\MRT.INI
2008-07-10 00:42 . 2008-07-10 00:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-08 13:12 . 2008-01-15 11:23 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Roxio
2008-07-08 13:12 . 2008-01-15 11:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-08 13:12 . 2008-07-08 13:12 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-07 22:01 . 2008-07-07 22:01 <DIR> d-------- C:\Program Files\AVG
2008-07-07 22:01 . 2008-07-07 22:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-06 17:32 . 2008-07-06 17:34 <DIR> d-------- C:\Documents and Settings\Norma Smith\Application Data\eBookPro6
2008-07-06 15:37 . 2006-12-05 19:52 505 --a------ C:\unPDVDDX.iss
2008-07-06 15:19 . 2008-07-06 15:19 <DIR> d-------- C:\Documents and Settings\Norma Smith\Application Data\CyberLink
2008-07-06 15:19 . 2008-07-06 15:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-06 00:10 . 2008-07-06 00:10 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-01 01:16 --------- d-----w C:\Program Files\Java
2008-07-29 19:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-28 02:47 --------- d-----w C:\Documents and Settings\Nicole\Application Data\Apple Computer
2008-07-27 22:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-25 02:03 --------- d-----w C:\Program Files\Roxio
2008-07-21 04:09 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-20 13:54 --------- d-----w C:\Program Files\Dell AIO Printer 948
2008-07-18 01:51 --------- d-----w C:\Program Files\LimeWire
2008-07-18 01:46 --------- d-----w C:\Documents and Settings\Norma Smith\Application Data\LimeWire
2008-07-18 01:40 --------- d-----w C:\Documents and Settings\Nicole\Application Data\LimeWire
2008-07-15 01:23 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-10 05:44 --------- d-----w C:\Program Files\Yahoo!
2008-07-08 02:25 --------- d-----w C:\Program Files\Common Files\Scanner
2008-07-07 22:36 --------- d-----w C:\Program Files\Trend Micro
2008-07-05 23:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-28 20:58 --------- d-----w C:\Documents and Settings\Norma Smith\Application Data\Corel
2008-06-26 12:51 --------- d-----w C:\Documents and Settings\Chelsea Smith\Application Data\Yahoo!
2008-06-24 05:47 --------- d-----w C:\Documents and Settings\Norma Smith\Application Data\Apple Computer
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 00:21 --------- d-----w C:\Program Files\DVDVideoSoft
2008-06-13 00:21 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft
2008-06-11 01:50 --------- d-----w C:\Documents and Settings\Norma Smith\Application Data\SecondLife
2008-02-06 18:40 1,377,872 ----a-w C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
.
((((((((((((((((((((((((((((( snapshot@2008-07-29_12.28.21.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-11-10 17:27:06 49,248 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 05:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2005-11-10 17:27:16 49,250 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 05:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2005-11-10 19:03:54 127,078 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 06:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 18:15 321040]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 11:23 202544]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35 67112]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 12:41 223984]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-15 11:16 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-09-28 14:30 936960]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-07-16 21:45 138008]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-06-08 18:40 128560]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 14:02 1807960]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 13:37 81920]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 13:35 221184]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-07-16 21:45 142104]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-07-16 21:45 162584]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-01-15 11:16 1838592]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-24 09:03 17920]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 11:24 16384]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2004-04-07 14:07 496752]
"MemoryCardManager"="C:\Program Files\Dell AIO Printer 948\memcard.exe" [2007-09-18 14:45 410280]
"Dell AIO Printer 948 Fax Server"="C:\Program Files\Dell AIO Printer 948\fm3032.exe" [2007-09-19 21:27 312560]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 12:41 223984]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 13:22 221184]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 11:23 202544]
"dldfmon.exe"="C:\Program Files\Dell AIO Printer 948\dldfmon.exe" [2007-09-18 14:45 455336]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe" [2007-03-21 02:33 478800]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-16 21:48 16132608 C:\WINDOWS\RTHDCPL.EXE]
C:\Documents and Settings\Nicole\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-01-10 14:08:24 147456]
C:\Documents and Settings\Norma Smith\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 05:45:42 101784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-01-15 11:04:35 24576]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)
"NoDispScrSavPage"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Dell AIO Printer 948\\dldfmon.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldfpswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldfjswx.exe"=
"C:\\Program Files\\Dell AIO Printer 948\\dldfaiox.exe"=
"C:\\Program Files\\Dell AIO Printer 948\\DLDFFax.exe"=
"C:\\Program Files\\Dell AIO Printer 948\\dldfafcn.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\WINDOWS\\system32\\dldfcoms.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldftime.exe"=
R2 dldf_device;dldf_device;C:\WINDOWS\system32\dldfcoms.exe [2007-06-26 07:56]
S3 Radialpoint Security Services;Radialpoint Security Services;C:\WINDOWS\system32\dllhost.exe [2004-08-04 07:00]
S4 dldfCATSCustConnectService;dldfCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\dldfserv.exe [2007-06-26 07:56]
.
Contents of the 'Scheduled Tasks' folder
2008-07-12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-31 21:46:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-07-31 21:49:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-01 01:49:28
ComboFix2.txt 2008-07-29 16:28:38
Pre-Run: 225,060,958,208 bytes free
Post-Run: 225,068,822,528 bytes free
247 --- E O F --- 2008-07-10 12:02:32